2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31321 | CRITICAL | 9.1 | 0.8% | Aug 1, 2022 | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform ... |
| CVE-2022-31190 | MEDIUM | 5.3 | 0.7% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui... |
| CVE-2022-31188 | CRITICAL | 9.8 | 47.8% | Aug 1, 2022 | CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were foun... |
| CVE-2022-31186 | LOW | 3.3 | 0.2% | Aug 1, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulner... |
| CVE-2022-31185 | MEDIUM | 5.3 | 0.5% | Aug 1, 2022 | mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, eve... |
| CVE-2022-31184 | HIGH | 7.5 | 0.6% | Aug 1, 2022 | Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen... |
| CVE-2022-31183 | CRITICAL | 9.8 | 0.6% | Aug 1, 2022 | fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on N... |
| CVE-2022-31182 | MEDIUM | 5.3 | 0.6% | Aug 1, 2022 | Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static asset... |
| CVE-2022-31181 | CRITICAL | 9.8 | 5.1% | Aug 1, 2022 | PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to ... |
| CVE-2022-31180 | CRITICAL | 9.8 | 1.5% | Aug 1, 2022 | Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of ... |
| CVE-2022-31179 | CRITICAL | 9.8 | 1.1% | Aug 1, 2022 | Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injec... |
| CVE-2022-31178 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged i... |
| CVE-2022-31177 | LOW | 2.7 | 0.6% | Aug 1, 2022 | Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.... |
| CVE-2022-31173 | HIGH | 7.5 | 1.3% | Aug 1, 2022 | Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resu... |
| CVE-2022-31155 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible fo... |
| CVE-2022-31154 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to ... |
| CVE-2022-31148 | MEDIUM | 5.4 | 0.5% | Aug 1, 2022 | Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerabi... |
| CVE-2022-31128 | MEDIUM | 5.4 | 0.5% | Aug 1, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi... |
| CVE-2022-31109 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP messa... |
| CVE-2022-34307 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to ... |
| CVE-2022-34164 | MEDIUM | 5.5 | 0.2% | Aug 1, 2022 | IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X... |
| CVE-2022-34163 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. Thi... |
| CVE-2022-34162 | MEDIUM | 6.1 | 0.7% | Aug 1, 2022 | IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi... |
| CVE-2022-34161 | HIGH | 8.8 | 0.4% | Aug 1, 2022 | IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2022-33955 | MEDIUM | 6.8 | 0.5% | Aug 1, 2022 | IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and r... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now